Multi-Layer Passwordless Authentication Across Active Directory Domains
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Operational technology (OT) and industrial control systems (ICS) environments face challenges in securing user access across multiple network layers due to the complexity of managing multiple user identities, password reuse, and susceptibility to replay attacks, which compromise security and management efficiency.
Innovation Solution
Implementing a computer-implemented method that combines multi-factor authentication with pre-configured hidden data in distributed ledgers for passwordless authentication, allowing users to traverse multiple network layers without remembering multiple passwords and eliminating the need for password input across the wire.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple user identities are created across multiple Active Directory servers or domains to grant access to different security zones, then access control capability is improved, but user complexity and management complexity increase
Solution Approach 1:
The patent implements a universal authentication mechanism where a single authentication token can be used across multiple Active Directory servers and security zones. The token-based approach allows one credential to serve multiple functions and access points, eliminating the need for users to manage separate passwords for each domain while maintaining the ability to control access to different security zones.
Solution Approach 2:
The patent introduces an authentication token as an intermediary between users and multiple Active Directory servers. Instead of users directly managing multiple credentials, the token acts as a mediator that authenticates users to various domains and security zones, simplifying the authentication process while maintaining comprehensive access control.
2Reliability
If users input passwords across the wire to access accounts, then authentication capability is maintained, but susceptibility to replay attacks increases
Solution Approach 1:
The patent replaces the traditional password transmission mechanism with a token-based authentication system. Instead of transmitting passwords across the wire, the system uses authentication tokens that are generated and validated locally, eliminating the vulnerability associated with transmitting password data over networks and thus preventing replay attacks.
Solution Approach 2:
The patent implements preliminary authentication where authentication tokens are generated in advance and stored securely. These pre-generated tokens are then used for authentication without requiring users to input passwords during the actual access attempt, ensuring that no password transmission occurs across the wire and eliminating replay attack risks.
3Ease of operation
If similar or the same password is used for multiple accounts to reduce complexity, then ease of operation is improved, but security of resources across multiple layers is reduced
Solution Approach 1:
The patent segments the authentication mechanism into two distinct parts: a static authentication token that remains the same across multiple domains, and dynamic domain-specific credentials that are generated on-demand. This segmentation allows users to remember a single token while maintaining security through domain-specific validation, preventing the security risks associated with password reuse.
Solution Approach 2:
The patent changes the authentication parameter from passwords to authentication tokens. The token itself remains constant across multiple domains (improving ease of operation), but the authentication process incorporates domain-specific parameters and validation rules (maintaining security). This parameter change resolves the contradiction by decoupling the credential from the domain-specific security requirements.
4Adaptability or versatility
If static accounts exist on jump boxes for access control, then access control capability is maintained, but management complexity increases when users change status
Solution Approach 1:
The patent transitions from static accounts to dynamic authentication. Instead of maintaining fixed user accounts in multiple Active Directory servers, the system dynamically generates and validates authentication tokens. This dynamic approach automatically adapts to user status changes without requiring manual account updates across multiple domains, reducing management complexity while maintaining access control capability.
Solution Approach 2:
The patent implements a feedback mechanism where authentication tokens are validated against current user status information in real-time. When user status changes (such as leaving the enterprise or contract expiration), the system receives feedback about the updated status and automatically adjusts authentication validity, eliminating the need for manual account deletion across multiple Active Directory servers while maintaining proper access control.
Data Source
AI summary
In one embodiment, a method includes receiving a first request to access one or more resources in the first network layer. The method may include acquiring first identity information of a first user account specified in the first request. The method may include performing multi-factor authentication of the first user account using the first identity information. In response to authenticating the first user account using the first identity information, the method may include acquiring multiple shares of pre-configured first hidden data from a distributed ledger in the first network layer. The method may include determining a first password from the multiple shares of pre-configured first hidden data and, using the first password, authenticating the first user account to access the one or more resources in the first network layer.


